Skip to content
GradioGHSA-3x5j-9vwr-8rr5

Update share links to use FRP instead of SSH tunneling

Medium5.4CVE-2023-25823 · Published Feb 23, 2023 · updated Sep 10, 2026

### Impact This is a vulnerability which affects anyone using Gradio's share links (i.e. creating a Gradio app and then setting `share=True`) with Gradio versions older than 3.13.1. In these older versions of Gradio, a private SSH key is sent to any user that connects to the Gradio machine, which means that a user could access other users' shared Gradio demos. From there, other exploits are possible depending on the level of access/exposure the Gradio app provides. ### Patches The problem has been patched. Ideally, users should upgrade to `gradio==3.19.1` or later where the FRP solution has been properly tested. ### Credit Credit to Greg Sadetsky and Samuel Tremblay-Cossette for alerting the team

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
< 3.13.13.13.1
Details and references

More Gradio advisories

All Gradio
Advisory
Gradio Path Traversal vulnerability
High7.5Feb 6, 2024
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
High8.6Dec 21, 2023
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Critical9.6Dec 14, 2023
Gradio arbitrary file upload vulnerability
Medium4.8Sep 16, 2023
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Medium7.3Jun 9, 2023
Improper Neutralization of Formula Elements in a CSV File in Gradio Flagging
High8.8Mar 18, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.